wp-perf-audit
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md’s runtime workflow ingests outsider-authored free text by fetching the operator-supplied WordPress public site URL and reading its returned markup/headers/content via scripts like
fingerprint.py,capabilities.py, andperf-probe.py(e.g., “Origin is measured with a unique cache-buster” and findings use “a page fetched from an audited site is untrusted input”).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata